CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,367 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,054 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-11811 | In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type val… | In your normal cycle | 9.8 critical | 3% | 2020-04-16 |
| CVE-2020-36157 | An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the… | In your normal cycle | 10.0 critical | 3% | 2021-01-04 |
| CVE-2026-19295 | IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving… | In your normal cycle | 9.9 critical | 3% | 2026-08-28 |
| CVE-2017-5440 | A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading… | In your normal cycle | 9.8 critical | 3% | 2018-06-11 |
| CVE-2017-5441 | A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable crash. This vulnerability affe… | In your normal cycle | 9.8 critical | 3% | 2018-06-11 |
| CVE-2017-5460 | A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a… | In your normal cycle | 9.8 critical | 3% | 2018-06-11 |
| CVE-2017-7800 | A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished.… | In your normal cycle | 9.8 critical | 3% | 2018-06-11 |
| CVE-2017-3272 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE… | In your normal cycle | 9.6 critical | 3% | 2017-01-27 |
| CVE-2017-2892 | An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT p… | In your normal cycle | 9.8 critical | 3% | 2017-11-07 |
| CVE-2015-1000001 | Remote file upload vulnerability in fast-image-adder v1.1 Wordpress plugin | In your normal cycle | 9.8 critical | 3% | 2016-10-06 |
| CVE-2024-9796 | The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unaut… | In your normal cycle | 9.8 critical | 3% | 2024-10-10 |
| CVE-2025-10644 | Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypa… | In your normal cycle | 9.4 critical | 3% | 2025-09-17 |
| CVE-2021-35209 | An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patch… | In your normal cycle | 9.8 critical | 3% | 2021-07-02 |
| CVE-2019-15260 | A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targete… | In your normal cycle | 9.8 critical | 3% | 2019-10-16 |
| CVE-2022-42468 | Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsaf… | In your normal cycle | 9.8 critical | 3% | 2022-10-26 |
| CVE-2014-8621 | SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via t… | In your normal cycle | 9.8 critical | 3% | 2017-10-16 |
| CVE-2018-1000810 | The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow… | In your normal cycle | 9.8 critical | 3% | 2018-10-08 |
| CVE-2019-17562 | A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vuln… | In your normal cycle | 9.8 critical | 3% | 2020-05-14 |
| CVE-2022-25134 | A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attack… | In your normal cycle | 9.8 critical | 3% | 2022-02-19 |
| CVE-2021-43329 | A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute arbitrary SQL c… | In your normal cycle | 9.8 critical | 3% | 2022-08-25 |
| CVE-2019-19790 | Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON… | In your normal cycle | 9.8 critical | 3% | 2019-12-13 |
| CVE-2007-5341 | Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8. | In your normal cycle | 9.8 critical | 3% | 2017-08-18 |
| CVE-2026-45744 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/fil… | In your normal cycle | 9.9 critical | 3% | 2026-06-05 |
| CVE-2026-8153 | OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft com… | In your normal cycle | 9.8 critical | 3% | 2026-05-08 |
| CVE-2021-43042 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploitab… | In your normal cycle | 9.8 critical | 3% | 2021-12-06 |
| CVE-2017-14378 | EMC RSA Authentication Agent API 8.5 for C and RSA Authentication Agent SDK 8.6 for C allow attackers to bypass authentication, aka an "Error Handling… | In your normal cycle | 10.0 critical | 3% | 2017-11-29 |
| CVE-2016-6178 | Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devices with so… | In your normal cycle | 9.8 critical | 3% | 2016-08-02 |
| CVE-2021-40391 | An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked… | In your normal cycle | 9.8 critical | 3% | 2021-11-19 |
| CVE-2021-21887 | A stack-based buffer overflow vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU).… | In your normal cycle | 9.1 critical | 3% | 2021-12-22 |
| CVE-2021-21890 | A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A… | In your normal cycle | 9.1 critical | 3% | 2021-12-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt